Vulnerabilities > CVE-2006-1206 - Unspecified vulnerability in Dropbear SSH Project Dropbear SSH
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Matt Johnston Dropbear SSH server 0.47 and earlier, as used in embedded Linux devices and on general-purpose operating systems, allows remote attackers to cause a denial of service (connection slot exhaustion) via a large number of connection attempts that exceeds the MAX_UNAUTH_CLIENTS defined value of 30.
Vulnerable Configurations
Exploit-Db
description | Dropbear / OpenSSH Server (MAX_UNAUTH_CLIENTS) Denial of Service. CVE-2006-1206. Dos exploits for multiple platform |
id | EDB-ID:1572 |
last seen | 2016-01-31 |
modified | 2006-03-10 |
published | 2006-03-10 |
reporter | str0ke |
source | https://www.exploit-db.com/download/1572/ |
title | Dropbear / OpenSSH Server MAX_UNAUTH_CLIENTS Denial of Service |
Nessus
NASL family | Denial of Service |
NASL id | DROPBEAR_30_DOS.NASL |
description | The remote host is running Dropbear, a small, open source SSH server. The version of Dropbear installed on the remote host, by default, has a limit of 30 connections in the authorization-pending state; subsequent connections are closed immediately. This issue can be exploited trivially by an unauthenticated attacker to deny service to legitimate users. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21023 |
published | 2006-03-08 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/21023 |
title | Dropbear SSH Authorization-pending Connection Saturation DoS |
code |
|
References
- http://securitytracker.com/id?1015742
- http://securitytracker.com/id?1015742
- http://www.securityfocus.com/archive/1/426999/100/0/threaded
- http://www.securityfocus.com/archive/1/426999/100/0/threaded
- http://www.securityfocus.com/bid/17024
- http://www.securityfocus.com/bid/17024
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25075
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25075